Developer platform

Give every app a
safer wallet path.

Use the hosted encrypted-vault API today. Keep application tenants isolated, require passkeys, and keep plaintext keys out of requests and logs.

client-boundary.js
// Your application
generateOrImportKey()
  → encryptInBrowser()
  → saveCiphertext()

// The service stores
{
  envelope,
  credential,
  revision
}

// The service never receives
decryptedKey | passkeyOutput
Service onlineAPI v1 · envelope v2
RangerEmbedded vault pilotLive pilot
Central connectorSeparate-origin signingRanger pilot

Choose the boundary

Two paths, one rule: the app never logs a key.

Passkeys are bound to a domain. Choose the model that matches where the wallet should live.

Available now

Embedded app vault

The app uses its own exact origin and host-scoped RP ID. Its encrypted records live in a separate tenant namespace.

  • Independent credentials per app
  • Copied, reviewed browser modules
  • Ranger pilot is the reference
Implementation contract
Available as Ranger pilot

Central wallet connector

The Ranger pilot opens a popup at this origin and keeps keys and transaction approval outside the app page. Each future subDAO needs an explicit origin registration and transaction policy.

  • One user-managed keyring
  • Independent transaction confirmation
  • No iframe or parent-domain RP shortcut
Pilot scope: Base USDC approval and canonical Ranger orders. ETH gas is required; existing dapp paymaster code stays in the dapp and awaits a remote signing adapter.

Everything you need